Gallery – Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 2, 2025
CVE-2023-45631 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Jul 6, 2024
CVE-2024-37542 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 8, 2024
CVE-2024-35750 on NVD →
Gallery – Image and Video Gallery with Thumbnails <= 2.0.3 - Authenticated (Contributor+) SQL Injection
critical
The Gallery – Image and Video Gallery with Thumbnails plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...
- CVSS:
- 9.9
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 6, 2024
CVE-2024-35750 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Reflected XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2024
CVE-2024-30550 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Stored XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2024
CVE-2024-31120 on NVD →
Responsive Image Gallery, Gallery Album <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 29, 2024
CVE-2024-31120 on NVD →
Responsive Image Gallery, Gallery Album <= 2.0.3 - Reflected Cross-Site Scripting
medium
The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 29, 2024
CVE-2024-30550 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)
unknown
[en] Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 18, 2023
CVE-2023-45630 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 16, 2023
CVE-2023-45629 on NVD →
Responsive Image Gallery, Gallery Album <= 2.0.3 - Unauthenticated Cross-Site Scripting
medium
The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 6.1
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2023
CVE-2023-45630 on NVD →
Responsive Image Gallery, Gallery Album <= 2.0.3 - Missing Authorization via Multiple AJAX Actions
medium
The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to missing capability checks on multiple AJAX functions in versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with subscriber-level access and a...
- CVSS:
- 5.4
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2023
CVE-2023-45631 on NVD →
Responsive Image Gallery, Gallery Album <= 2.0.3 - Cross-Site Request Forgery
medium
The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.3. This is due to missing or incorrect nonce validation multiple functions. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged...
- CVSS:
- 5.4
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2023
CVE-2023-45629 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] < 2.0.2 (closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions.
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Mar 29, 2023
CVE-2022-47603 on NVD →
Gallery – Image and Video Gallery with Thumbnails <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting
high
The Responsive Image and video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$_GET["id"]’ parameter in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- CVSS:
- 7.2
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Feb 3, 2023
CVE-2022-47603 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] < 2.0.0 (closed)
unknown
[en] The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Jul 4, 2022
CVE-2022-1946 on NVD →
Gallery – Image and Video Gallery with Thumbnails <= 1.9.9 - Reflected Cross-Site Scripting
medium
The Gallery – Image and Video Gallery with Thumbnails plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping on the gallery_current_index parameter supplied via the wp_ajax_wpda_gall_load_image_info AJAX act...
- CVSS:
- 6.1
- Affected:
- up to 1.9.9
- Fixed in:
- 2.0.0
- Disclosed:
- Jun 13, 2022
CVE-2022-1946 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] < 1.2.1 (closed)
unknown
[en] SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
- Disclosed:
- Sep 25, 2017
CVE-2017-14125 on NVD →
Gallery – Image and Video Gallery with Thumbnails [gallery-album] < 1.2.1 (closed)
unknown
Authenticated SQL Injection vulnerability found by Manuel García Cárdenas in WordPress Responsive Image Gallery, Gallery Album version 1.2.0 and earlier versions.<br />
Update the Responsive Image Gallery, Gallery Album plugin to the latest available version (at least 1.2.1).<br />
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
- Disclosed:
- Sep 25, 2017
Gallery – Image and Video Gallery with Thumbnails < 1.2.1 - SQL Injection
critical
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
- CVSS:
- 9.8
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
- Disclosed:
- Sep 22, 2017
CVE-2017-14125 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database